Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-44964

Опубликовано: 29 нояб. 2021
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

A flaw was found in the Lua interpreter. This flaw allows an attacker who can have a malicious script executed by the interpreter, to cause a use-after-free issue that may result in a sandbox escape.

Отчет

This flaw does not affect versions of Lua shipped with Red Hat Enterprise Linux 6, 7, or 8; the vulnerable code was introduced in a subsequent version of Lua.

Меры по смягчению последствий

Ensure that the Lua interpreter runs only trusted scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6luaNot affected
Red Hat Enterprise Linux 7luaNot affected
Red Hat Enterprise Linux 8libreoffice:flatpak/luaNot affected
Red Hat Enterprise Linux 8luaNot affected
Red Hat JBoss Core ServicesluaNot affected
Red Hat Enterprise Linux 9luaFixedRHSA-2023:095728.02.2023
Red Hat Enterprise Linux 9luaFixedRHSA-2023:095728.02.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportluaFixedRHSA-2023:121114.03.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2064772lua: use after free allows Sandbox Escape

EPSS

Процентиль: 28%
0.00097
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVSS3: 6.3
nvd
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVSS3: 6.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.3
debian
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua inte ...

CVSS3: 6.3
github
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

EPSS

Процентиль: 28%
0.00097
Низкий

7 High

CVSS3

Уязвимость CVE-2021-44964